Threat context

Fake QR stickers are real. “Stop all phishing” is not what we sell.

Attackers overlay printed QR codes (menus, parking meters, posters) with stickers that point to lookalike sites. The risk is social engineering plus a camera that opens a URL with almost no context.

What signed QR codes actually help with

  • If your business issues QRalo-signed codes and people verify them, a swapped sticker that is not a valid QRalo signature fails verification.
  • If someone forges a payload, the signature check fails.
  • If a legitimate code is compromised, you can revoke it so verification refuses the redirect.
  • At create/scan time we can check the destination against known-malicious URL lists. That catches listed threats — not every brand-new phishing page.

What it does not do

  • It does not protect someone who scans a random non-QRalo sticker with a normal camera and never sees a verification step.
  • It is not a guarantee that a destination website is “safe forever.”
  • It is not antivirus for the phone.

Practical advice for businesses

  1. Issue signed QR codes for high-trust surfaces (menus, payments, parking).
  2. Put a short note next to the print: “Verify on qralo.com/scan” or use the verify URL flow.
  3. Revoke and reprint if a sticker is damaged or suspected swapped.
  4. Prefer your own verified domain on the destination when possible.

Related guides

Issue signed codes for the stickers you control

Free plan includes 3 signed QR codes. Honesty over hype.

Create signed QR codes